alertmanager / alert_manager

Splunk Alert Manager with advanced reporting on alerts, workflows (modify assignee, status, severity) and auto-resolve features
Other
81 stars 43 forks source link

Upgrade to "alert_users" macro #297

Open greggwoodcock opened 3 years ago

greggwoodcock commented 3 years ago

This adds other detail AND eliminates several warnings: rest/services/admin/alert_manager/settings splunk_server=local | fields default_owner | rename default_owner AS name | append [ makeresults | eval name="unassigned" | eval realname ="Placeholder 'NULL' non-User" ] | fields - _time | append [ inputlookup alert_users | sort name | fields name ] | append [| rest/services/authentication/users splunk_server=local | search roles="alert_manager" | dedup title realname | table title realname email type roles | table title realname | rename title AS name ] | stats values() AS BY name | sort 0 name